|
285151
|
- |
|
apache
|
tomcat
|
java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0096
|
2024-11-21 11:01 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285152
|
- |
|
apache
|
tomcat
|
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP req…
|
CWE-20
Improper Input Validation
|
CVE-2014-0095
|
2024-11-21 11:01 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285153
|
- |
|
apache
|
tomcat
|
Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 allows remot…
|
CWE-189
Numeric Errors
|
CVE-2014-0075
|
2024-11-21 11:01 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285154
|
- |
|
redhat
|
rhevm-dwh
|
The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh) package before 3.3.3, stores the history database password in cleartext, whic…
|
CWE-255
Credentials Management
|
CVE-2014-0202
|
2024-11-21 11:01 |
2014-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285155
|
- |
|
sosreport_project
|
sosreport
|
SOSreport stores the md5 hash of the GRUB bootloader password in an archive, which allows local users to obtain sensitive information by reading the archive.
|
CWE-255
Credentials Management
|
CVE-2014-0246
|
2024-11-21 11:01 |
2014-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285156
|
- |
|
redhat
|
rhevm-reports
|
ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0201
|
2024-11-21 11:01 |
2014-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285157
|
- |
|
redhat
|
rhevm-reports
|
The Red Hat Enterprise Virtualization Manager reports (rhevm-reports) package before 3.3.3-1 uses world-readable permissions on the datasource configuration file (js-jboss7-ds.xml), which allows loca…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0200
|
2024-11-21 11:01 |
2014-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285158
|
- |
|
redhat
|
rhevm-reports
|
The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) package before 3.3.3, stores the reports database password in cleartext, which allow…
|
CWE-310
Cryptographic Issues
|
CVE-2014-0199
|
2024-11-21 11:01 |
2014-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285159
|
- |
|
samba
|
samba
|
The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a response, which allows remote attackers to cause a den…
|
CWE-20
Improper Input Validation
|
CVE-2014-0239
|
2024-11-21 11:01 |
2014-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285160
|
- |
|
samba
|
samba
|
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, w…
|
CWE-665
Improper Initialization
|
CVE-2014-0178
|
2024-11-21 11:01 |
2014-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|